Mô tả

Splunk 2022 - Beginner to Architect is a course specifically designed for beginners who intends to master the infrastructure side of Splunk.

This course starts from absolute scratch, and step by step, we build a solid foundation in Splunk to master various aspects related to writing SPL queries, building dashboards, deploying a distributed Splunk architectures, Troubleshooting, Access controls, as well as building highly available clustered setup for Splunk.

We also discuss the traditional and the newer Splunk deployment models, both via the RPM-based approach and the newer Docker containers approach, which provide benefits of deploying Splunk in any platform, including local laptops just within two minutes. This allows quick testing as well as quicker deployments within production environments.

Individuals, post completing this course, will have a solid understanding of Splunk components as well as be able to deploy production level Splunk clusters in their organizations that are highly available and can handle traffic at scale.

With a beginner-friendly course, tons of practicals, easy-to-understand videos, and great Support from our Instructor in case of doubts, this course is all you need to build a solid foundation in Splunk.

With this interesting set of learnings and practicals, I look forward to seeing you in this course.

Bạn sẽ học được gì

Build Highly Available Clustering Architectures

Design and Create Dashboards to detect anomalies

Implementing Splunk in Docker Containers

Troubleshooting and Industry Best Practices in Managing Splunk

Yêu cầu

  • Computer with Internet Connection

Nội dung khoá học

11 sections

Getting Started

3 lectures
Introduction to the Course
02:40
Download Links - Tutorial Data, Samples and Logs
00:06
Our Community
00:12

Introduction to Splunk & Setting Up Labs

17 lectures
Introduction to Splunk
06:50
Installation Methods for Splunk
09:10
Document - MSSP
00:01
Creating Splunk Account
03:57
Launching Infrastructure for Splunk
12:37
Installing Splunk in Linux
06:52
Document - Splunk Install Commands for Linux
00:11
Installing Splunk in Windows
03:57
Introduction to Docker Containers - New
11:01
Installation Methods for Docker
06:37
Installing Docker in Linux
02:56
Document - Linux Installation Commands
00:14
Installing Docker Desktop
03:43
Document - Docker Desktop
00:01
Deploying Splunk Docker Container
11:27
Document - Deploying Splunk Container Commands
00:05
Notes - Domain 1
00:00

Getting started with Splunk

15 lectures
Importing Data in Splunk
12:45
Sample Tutorial Logs
00:05
Parsing Authentication Logs
05:11
Security Use-Case - Finding Attack Vectors
14:57
Basics of Search
13:59
Splunk Search Assistant
04:24
Splunk Reports
06:39
Splunk Report - Email Clarification (Followup)
01:22
Understanding Add-Ons and Apps
13:40
Installing Splunk Add-On for AWS
15:37
Overview of Dashboards and Panels
13:10
Building Dashboard Inputs - Time Range Picker
07:08
Building Dashboard Inputs - Text Box
04:51
Building Dashboard Inputs - Drop down
02:44
Notes - Domain 2
00:00

Splunk Architecture

12 lectures
Directory Structure of Splunk
10:48
Splunk Configuration Directories
11:44
Splunk Configuration Precedence
06:09
Splunk Configuration Precedence - Apps and Locals
04:05
Introduction to Indexes
12:36
Document - Reference Commands
00:02
Bucket Lifecycle
17:19
Warm to Cold Bucket Migration
07:28
Archiving Data to Frozen Path
08:14
Thawing Process
06:21
Splunk Workflow Actions
05:58
Notes - Domain 3
00:00

Forwarder & User Management

11 lectures
Overview of Universal Forwarders
04:26
Installing Universal Forwarder in Linux
12:53
Installation Manual - Splunk Universal Forwarder
00:17
Challenges in Forwarder Management
06:57
Introduction to Deployment Server
08:43
Document - Enable Deployment Server
00:01
ServerClass and Deployment Apps
08:05
Document - Connecting to Deployment Server
00:19
Pushing Custom Add-On via Deployment Server
10:20
Document - Commands
00:19
Notes - Domain 4
00:00

Post Installation Activities

14 lectures
Understanding Regular Expressions
15:49
Regex - Exercise
00:07
Parsing Web Server Logs & Named Group Expression
10:05
Sample - Web Server Logs
00:03
Importance of Source Types
07:41
Interactive Field Extractor (IFX)
05:50
props.conf and transforms.conf
16:43
Sample Log - MySQL Error Logs
00:00
Splunk Event Types
06:15
Tags
06:53
Splunk Events Types Priority and Coloring Scheme
07:12
Splunk Lookups
13:51
Splunk Alerts
07:17
Notes - Domain 5
00:00

Security Primer

3 lectures
Access Control
10:26
Creating Custom Roles & Capabilities
10:51
Notes - Domain 6
00:00

Distributed Splunk Architecture

9 lectures
Overview of Distributed Splunk Architecture
07:14
Understanding License Master
05:06
Implementing License Master
05:43
License Pools
06:12
Indexer
04:51
Masking Sensitive Data at Index Time
06:17
Search Head
03:50
Splunk Monitoring Console
06:32
Notes - Domain 7
00:00

Indexer Clustering

14 lectures
Our Community
00:12
Overview of Indexer Clustering
04:19
Infrastructure for Indexer Cluster
02:39
Configuring Master Indexer
06:23
Configuring Peer Indexers
03:13
Testing Replication Capabilities
03:06
Testing Failover Capabilities
06:06
Configuration Bundles of Master Indexers
08:52
Document - indexes.conf
00:03
Forwarding Logs to Indexer Cluster
08:55
Document - Referenced Commands
00:13
Implementing Indexer Discovery
07:16
Indexer Discovery - Document
00:11
Notes - Domain 8
00:00

Search Head Clustering

10 lectures
Overview of Search Head Clustering
05:09
Infrastructure for Search Head Cluster
01:53
Setting Up Search Head Clustering
07:32
Document - Search Head Cluster Setup
00:07
Validating Search Head Replication
03:51
Pushing Artifacts through Deployer
05:37
Document - Pushing Bundle Setup
00:02
Integration - Search Head Cluster to Indexer Cluster
04:19
SH to IDX Cluster Document
00:02
Notes - Domain 9
00:00

Advanced Splunk Concepts

5 lectures
Using Btool for Troublshooting
08:53
Overview of Data Models
05:09
Creating Data Model - Practical
13:31
Splunk Support Programs
08:06
Notes - Domain 10
00:00

Đánh giá của học viên

Chưa có đánh giá
Course Rating
5
0%
4
0%
3
0%
2
0%
1
0%

Bình luận khách hàng

Viết Bình Luận

Bạn đánh giá khoá học này thế nào?

image

Đăng ký get khoá học Udemy - Unica - Gitiho giá chỉ 50k!

Get khoá học giá rẻ ngay trước khi bị fix.